GDPR & EU AI Act

    Real obligations, set out in the open.

    Written for the people who have to sign things off: legal, compliance, IT and procurement. It covers our role, our legal bases, where data goes, and how the EU AI Act applies to what we build.

    Nothing here is legal advice about your own obligations. It is a statement of ours.

    Last updated: August 11th, 2026

    Part A

    GDPR

    01 · Who is responsible for what

    Two relationships. They work differently.

    The most important thing to establish is which of us is doing what with the data.

    Website, demo requests, and accounts

    Attitude Group Ltd is the data controller.

    We decide what to collect and why: your name, work email, company, job title, and how you use the platform. This is covered in our Privacy Policy. Privacy Policy

    Your Company Brain and connected systems

    You are the data controller. We are the data processor.

    You decide what data enters the platform and what the agents do with it. We process it on your documented instructions and for no other purpose.

    That distinction matters in practice. It means we do not decide what your agents do with personal data, we do not repurpose your data for our own ends, and we do not answer requests from your employees or customers about their data. We route them to you and help you answer.

    The terms of that processing relationship are set out in a Data Processing Agreement, which reflects the requirements of Article 28 GDPR: subject matter and duration, purpose, categories of data and data subject, confidentiality, security measures, subprocessing, assistance with rights requests, and deletion or return of data. It is available to clients on request at [email protected].

    02 · Applicable law

    Attitude Group Ltd is registered in England.

    We process personal data subject to:

    • the UK GDPR and the Data Protection Act 2018, for our UK operations and clients
    • the EU GDPR (Regulation (EU) 2016/679), where we process the data of individuals in the EEA, including our clients in Italy, Malta and across Europe

    Where the two regimes differ, we apply the standard that offers the higher level of protection.

    03 · What we process, and on what legal basis

    Two roles. Two different answers.

    As controller: website visitors, prospects and account holders

    PurposeDataLegal basis
    Providing and administering your accountName, email, company, role, usage dataContract (Art. 6(1)(b))
    Billing and paymentBilling details, invoicing dataContract / legal obligation
    Support and communicationContact details, correspondenceContract / legitimate interests
    Product analytics and improvementUsage and technical dataLegitimate interests (Art. 6(1)(f))
    Security, fraud prevention, abuse monitoringTechnical and access dataLegitimate interests
    Marketing communicationsContact detailsConsent (Art. 6(1)(a)), withdrawable at any time
    Legal and regulatory complianceAs requiredLegal obligation (Art. 6(1)(c))

    Where we rely on legitimate interests, we assess that interest against the rights and freedoms of the individuals concerned.

    As processor: data inside your Company Brain and your agent workflows

    We process whatever categories of personal data you choose to place in the platform or expose through your connected systems. Depending on the workflows you build, that may include employee, candidate, customer or supplier data. Establishing the legal basis for that processing is your responsibility as controller. Ours is to process it only as instructed, and to give you the controls to do so lawfully.

    04 · Your uploaded data

    The commitments here are absolute, not best-efforts.

    • We do not use your data to train AI models.

      Not ours, not anyone's, not general-purpose models, not fine-tuning. This is binding on us and on the model providers we use.

    • We do not share your data with other customers.

      Each client's knowledge base, integrations and agent workflows are logically separated.

    • We do not sell personal data.

    • You retain ownership.

      Your content is yours. Our licence to it exists solely to deliver the service and ends when the relationship does.

    • Agents work through your systems.

      Data is read from and written to the platforms you already use, inheriting the role-based permissions configured there. We do not build a parallel copy of your business inside a Growy database.

    05 · Subprocessors

    A limited set, each held to our own terms.

    We use a limited set of subprocessors. Each is bound by a written contract imposing data protection obligations no less protective than our own, and each is assessed before engagement and reviewed thereafter.

    They fall into these categories:

    • Cloud infrastructure and hosting
    • Large language model providers: Anthropic, OpenAI, Google
    • Integration infrastructure: the connection layer that allows agents to reach your third-party systems
    • Operational tooling: email delivery, product analytics, support, payment processing

    The current named subprocessor list forms part of our Data Processing Agreement and is available on request at [email protected]. We inform clients of material changes to our subprocessors.

    06 · Model providers and your data

    The point most reviewers probe. So, to be explicit:

    When an agent or assistant runs, the relevant content is sent to a model provider to generate the output.

    • Data is sent only to produce a response or complete a task within your account.
    • Every provider operates under terms that prohibit training on customer data.
    • Providers are contractually barred from retaining or reusing your data beyond fulfilling the request.
    • Transmission is encrypted.

    Model selection is made per task on capability, reliability and cost. We review providers on an ongoing basis and may change them. Material changes affecting how client data is processed are communicated to affected clients.

    07 · International transfers

    Where data leaves the UK or EEA, it travels under a safeguard.

    Personal data may be processed outside the UK or EEA, principally because some model and infrastructure providers operate in the United States.

    Where that happens, transfers are made under an appropriate Article 46 safeguard: Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, or under an adequacy decision where one applies. We assess transfers and apply supplementary technical measures where required, principally encryption in transit and at rest.

    08 · Retention

    Set out in our Privacy Policy, and governed by your instructions.

    Retention periods for each category of data are set out in our Privacy Policy.

    For data we process on your behalf as processor, retention is governed by your instructions and your agreement with us. On termination you may export your content in a commonly used, machine-readable format. After 30 days we delete it from live systems, with backup copies expiring on our standard backup cycle.

    Deletion requests are actioned within 30 days.

    09 · Individual rights

    Who to contact depends on whose workspace your data is in.

    You're a Growy client, prospect, or website visitor

    Where we are the controller of your data, you may exercise your rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent by writing to [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. You also have the right to complain to a supervisory authority: the ICO in the UK, or your national authority in the EEA.

    Your data sits inside a client's Growy workspace

    That client is the controller and you should contact them directly. We assist our clients in responding: the platform allows client administrators to locate, export, correct and delete records, and we support them where a request cannot be fulfilled through the interface alone.

    10 · Automated decision-making

    Consequential decisions about people are made by people.

    Article 22 GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

    Growy agents are designed so that decisions of that kind are not made by the agent. Where a workflow touches an outcome affecting an individual: a hiring decision, a disciplinary step, a performance assessment, an eligibility determination: the platform is configured so that a person makes the decision, with the agent preparing, summarising or presenting information for that person to act on.

    Our node builder supports mandatory approval steps, escalation paths and confidence thresholds precisely so that this line is enforced in the workflow itself rather than only stated as a policy. Where a client wishes to configure a workflow that could approach Article 22 territory, we raise it during scoping.

    11 · Security

    Encryption, access control, and audit logging by default.

    Encryption in transit and at rest, role-based access control, logically separated client environments, workflow and node-level audit logging, and permissions inherited from your source systems.

    Full detail on our Security & Permissions page

    Access controls and safeguards, explained end to end.

    Security & Permissions

    12 · Personal data breaches

    Notification, either way, without undue delay.

    As processor

    If we become aware of a personal data breach affecting data we process on your behalf, we notify you without undue delay, with the information you need to meet your own obligations as controller.

    As controller

    We notify the relevant supervisory authority within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, and we notify affected individuals without undue delay where that risk is high, in line with Articles 33 and 34.

    13 · Data protection impact assessments

    We provide what your DPIA needs.

    Where your use of Growy requires a DPIA: likely for systematic monitoring, large-scale processing of special category data, or workflows involving employee data, we provide the information you need to complete it: data flows, subprocessors, retention, security measures, and the specific role of AI in the workflow. Request this at [email protected].

    Part B

    The EU AI Act

    14 · Where we sit in the Act

    The Act allocates obligations by role.

    The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. It matters which role each party holds.

    Growy

    Provider of an AI system

    We develop and place the Growy platform on the market under our own name.

    You

    The deployer

    When you configure agents and run them in your organisation, you use an AI system under your own authority. Deployer obligations sit with you. We build the platform so that you can meet them.

    Model providers

    Providers of general-purpose AI models

    Anthropic, OpenAI and Google carry the GPAI obligations for the models themselves, which have applied since 2 August 2025.

    We are explicit about this split because vendors who blur it tend to be overstating what they have taken off your plate.

    15 · Risk classification

    Risk attaches to the use case, not the software.

    Most Growy deployments: operational reporting, document retrieval, internal coordination, administrative workflow, supplier and sales operations: sit in the minimal risk category, with limited risk transparency obligations applying wherever a person interacts with an AI system or receives AI-generated content.

    Some workflows require more care. Annex III of the Act designates certain employment and worker-management uses as high risk, including recruitment, candidate screening and evaluation, allocation of tasks, and monitoring or evaluation of performance. Growy is used in HR and onboarding contexts, so this is live territory rather than theoretical.

    Our approach

    • Every deployment is classified with the client before it goes live, and the classification is recorded.
    • Where a workflow is in or near Annex III scope, we say so rather than assume it away.
    • We design such workflows so that the agent prepares and the person decides, which in most cases keeps the deployment assistive rather than determinative.
    • Where a use case genuinely falls within high-risk scope, we support the client on the deployer obligations that follow: human oversight, relevance of input data, log retention, and informing affected workers, and document the system accordingly.
    • If a workflow's purpose changes, its classification is reassessed. We ask clients to tell us when that happens.

    We do not build systems for biometric identification or categorisation, emotion inference in workplaces or education, social scoring, predictive policing, or any practice prohibited under Article 5, which has applied since 2 February 2025.

    16 · Transparency

    Article 50 obligations have applied since 2 August 2026.

    • Interactions with Growy AI Assistants and AI Agents are identified as AI-powered.
    • Where an agent produces content that reaches an individual, we support clients in disclosing its AI origin, and configure workflows so that disclosure is built into the output rather than added afterwards.
    • Machine-readable marking of AI-generated content under Article 50(2) applies to systems already on the market from 2 December 2026. We are addressing this within our product roadmap where it applies to our outputs.

    17 · AI literacy

    Article 4 has required this since 2 February 2025.

    Providers and deployers must take measures to ensure a sufficient level of AI literacy among the staff operating AI systems on their behalf.

    Internally, our teams are trained on the capabilities, limitations and risks of the systems we build. For clients, every deployment includes handover covering what the agent does, where it can fail, where human judgement is required, and how to pause or override it. We treat this as part of delivery, not an optional extra.

    18 · Compliance timeline

    Following the Digital Omnibus on AI, adopted in 2026.

    DateWhat applies
    2 February 2025Prohibited practices (Art. 5); AI literacy (Art. 4)
    2 August 2025Obligations for general-purpose AI models
    2 August 2026Article 50 transparency obligations; general application
    2 December 2026Art. 50(2) marking for systems already on the market; new prohibitions added by the Omnibus
    2 December 2027High-risk obligations for stand-alone Annex III systems
    2 August 2028High-risk obligations for AI embedded in Annex I regulated products

    The deferral of the high-risk deadlines changed the timing, not the substance. We build against the requirements now rather than treating 2027 as distance.

    19 · Documentation available to clients

    On request, we provide:

    • our Data Processing Agreement, including the subprocessor list and transfer safeguards
    • information to support your DPIA
    • a description of the AI system, its intended purpose, capabilities and known limitations
    • the risk classification record for your deployment
    • a security overview, and responses to your security questionnaire where required
    • audit log extracts for your own workflows

    Request any of these at [email protected].

    20 · What we ask of you

    Compliance here is genuinely shared.

    As controller and deployer, you are responsible for:

    • establishing a lawful basis for the personal data you place in the platform
    • informing your own data subjects, including employees, about the processing
    • keeping permissions in your connected systems accurate, since agents inherit them
    • deciding where human approval belongs in your workflows
    • reviewing agent outputs before acting on consequential ones
    • telling us when a workflow's purpose materially changes

    21 · Contact

    Questions about how this works? Ask directly.

    [email protected]Attitude Group Ltd.: 2 Alderney Court, Montague Street, Reading, England, RG1 4JW, United Kingdom